5
CVSSv2

CVE-2007-4937

Published: 18/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote malicious users to obtain the admin name and MD5 password hash via a direct request for base/usr/0.php.

Vulnerable Product Search on Vulmon Subscribe to Product

comscripts cs guestbook

Exploits

source: wwwsecurityfocuscom/bid/25652/info CS-Guestbook is prone to an information-disclosure vulnerability because the application fails to properly protect sensitive information An attacker can exploit this issue to access sensitive information that may lead to further attacks wwwexamplecom/guest/base/usr/0php ...